Novo Nordisk Hit by Cyber Incident, Probes Data Breach
Danish pharmaceutical group Novo Nordisk has confirmed a cyber security incident and is investigating a potential data breach. An extortion group identifying itself as FulcrumSec has claimed responsibility, asserting it stole approximately 1.3 TB of data and demanded a $25 million ransom, with reports indicating data was published after non-payment. Alleged contents include clinical data and AI-related intellectual property. Novo Nordisk has not confirmed the scope of data exposed, the attack vector, or any operational impact.
AI-generated from linked source reports. See our correction policy.
Impact verdict
High impact. HIGH-MEDIUM escalation: Multiple corroborating sources now support a credible extortion narrative with specific data volume, ransom demand, and actor attribution claims. Alleged exfiltration of clinical data and AI intellectual property from a major global pharmaceutical company elevates notification, regulatory (GDPR/Danish DPA), and third-party liability pathways. Materiality is constrained by the absence of confirmed manufacturing/supply disruption, the unverified status of the threat actor's claims, and lack of disclosed financial loss estimates. London Market relevance is direct for cyber syndicates carrying large-cap pharma risks, with possible read-across to Casualty (regulatory) and Property BI (if operations are disrupted).
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts